spaceapplications kayıtları
spaceapplications üreticisine ait 14 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %71,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-862 Missing Authorization1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-284 Improper Access Control1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
14 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2026-44596Kavram kanıtı | Yamcs: No Rate Limiting on Authentication Endpointspaceapplications · yamcs · CWE-307 | Kritik9,8 | — | %2,1 | 16 Tem 2026 |
39İzleyin | CVE-2026-46562İstismar yok | Yamcs: Remote Code Execution via Mission Database algorithm overridespaceapplications · yamcs · CWE-94 | Kritik9,8 | — | %1,0 | 16 Tem 2026 |
36İzleyin | CVE-2023-45278İstismar yok | Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via crafspaceapplications · yamcs · CWE-22 | Kritik9,1 | — | %1,6 | 19 Eki 2023 |
36İzleyin | CVE-2026-46621İstismar yok | Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injectionspaceapplications · yamcs · CWE-94 | Kritik9,1 | — | %1,1 | 16 Tem 2026 |
36İzleyin | CVE-2026-44632İstismar yok | Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`spaceapplications · yamcs · CWE-94 | Kritik9,1 | — | %1,1 | 16 Tem 2026 |
30İzleyin | CVE-2023-45277Kavram kanıtı | Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2).spaceapplications · yamcs · CWE-22 | Yüksek7,5 | — | %1,0 | 19 Eki 2023 |
24İzleyin | CVE-2023-47311İstismar yok | An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.spaceapplications · yacms · CWE-1021 | Orta6,1 | — | %0,4 | 20 Kas 2023 |
24İzleyin | CVE-2023-45281İstismar yok | An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.spaceapplications · yamcs · CWE-79 | Orta6,1 | — | %0,4 | 19 Eki 2023 |
21İzleyin | CVE-2023-46470İstismar yok | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via craftspaceapplications · yacms · CWE-79 | Orta5,4 | — | %0,6 | 20 Kas 2023 |
21İzleyin | CVE-2023-46471İstismar yok | Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the tspaceapplications · yacms · CWE-79 | Orta5,4 | — | %0,6 | 20 Kas 2023 |
21İzleyin | CVE-2023-45280İstismar yok | Yamcs 5.8.6 allows XSS (issue 2 of 2).spaceapplications · yamcs · CWE-79 | Orta5,4 | — | %0,5 | 19 Eki 2023 |
21İzleyin | CVE-2023-45279İstismar yok | Yamcs 5.8.6 allows XSS (issue 1 of 2).spaceapplications · yamcs · CWE-79 | Orta5,4 | — | %0,4 | 19 Eki 2023 |
17İzleyin | CVE-2026-44595Kavram kanıtı | Yamcs: Unauthorized user enumeration via IAM API endpointsspaceapplications · yamcs · CWE-862 | Orta4,3 | — | %1,1 | 16 Tem 2026 |
17İzleyin | CVE-2026-55548İstismar yok | Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packetsspaceapplications · yamcs · CWE-284 | Orta4,3 | — | %0,4 | 16 Tem 2026 |
- CVE-2026-4459640Planlayın
Yamcs: No Rate Limiting on Authentication Endpoint
KritikCVSS 9,8Kavram kanıtıEPSS %2spaceapplications · yamcs16 Tem 2026
- CVE-2026-4656239İzleyin
Yamcs: Remote Code Execution via Mission Database algorithm override
KritikCVSS 9,8İstismar yokEPSS %1spaceapplications · yamcs16 Tem 2026
- CVE-2023-4527836İzleyin
Directory Traversal vulnerability in the storage functionality of the API in Yamcs 5.8.6 allows attackers to delete arbitrary files via craf
KritikCVSS 9,1İstismar yokEPSS %2spaceapplications · yamcs19 Eki 2023
- CVE-2026-4662136İzleyin
Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
KritikCVSS 9,1İstismar yokEPSS %1spaceapplications · yamcs16 Tem 2026
- CVE-2026-4463236İzleyin
Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
KritikCVSS 9,1İstismar yokEPSS %1spaceapplications · yamcs16 Tem 2026
- CVE-2023-4527730İzleyin
Yamcs 5.8.6 is vulnerable to directory traversal (issue 1 of 2).
YüksekCVSS 7,5Kavram kanıtıEPSS %1spaceapplications · yamcs19 Eki 2023
- CVE-2023-4731124İzleyin
An issue in Yamcs 5.8.6 allows attackers to send aribitrary telelcommands in a Command Stack via Clickjacking.
OrtaCVSS 6,1İstismar yokEPSS %0spaceapplications · yacms20 Kas 2023
- CVE-2023-4528124İzleyin
An issue in Yamcs 5.8.6 allows attackers to obtain the session cookie via upload of crafted HTML file.
OrtaCVSS 6,1İstismar yokEPSS %0spaceapplications · yamcs19 Eki 2023
- CVE-2023-4647021İzleyin
Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via craft
OrtaCVSS 5,4İstismar yokEPSS %1spaceapplications · yacms20 Kas 2023
- CVE-2023-4647121İzleyin
Cross Site Scripting vulnerability in Space Applications Services Yamcs v.5.8.6 allows a remote attacker to execute arbitrary code via the t
OrtaCVSS 5,4İstismar yokEPSS %1spaceapplications · yacms20 Kas 2023
- CVE-2023-4528021İzleyin
Yamcs 5.8.6 allows XSS (issue 2 of 2).
OrtaCVSS 5,4İstismar yokEPSS %1spaceapplications · yamcs19 Eki 2023
- CVE-2023-4527921İzleyin
Yamcs 5.8.6 allows XSS (issue 1 of 2).
OrtaCVSS 5,4İstismar yokEPSS %0spaceapplications · yamcs19 Eki 2023
- CVE-2026-4459517İzleyin
Yamcs: Unauthorized user enumeration via IAM API endpoints
OrtaCVSS 4,3Kavram kanıtıEPSS %1spaceapplications · yamcs16 Tem 2026
- CVE-2026-5554817İzleyin
Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets
OrtaCVSS 4,3İstismar yokEPSS %0spaceapplications · yamcs16 Tem 2026